Snort mailing list archives
Re: Detecting slow portscans with snort
From: Martin Roesch <roesch () sourcefire com>
Date: Mon, 24 Jan 2005 10:41:33 -0500
Define a "slow" portscan. There's a new portscan detector in 2.3RC2 (sfportscan) that you might want to check out, we're planning on deprecating all the other portscan detection mechanisms in Snort once it's had a good shakedown and has been accepted by the community.
-Marty On Jan 23, 2005, at 12:33 PM, Bjarte Malmedal wrote:
How should conversation/portscan2 be configured to catch slow portscans?Bjarte ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
-- Martin Roesch - Founder/CTO, Sourcefire Inc. - +1-410-290-1616 Sourcefire - Discover. Determine. Defend. roesch () sourcefire com - http://www.sourcefire.com Snort: Open Source Network IDS - http://www.snort.org ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Detecting slow portscans with snort Bjarte Malmedal (Jan 24)
- Re: Detecting slow portscans with snort Martin Roesch (Jan 24)
- Re: Detecting slow portscans with snort Matt Kettler (Jan 24)
- Re: Detecting slow portscans with snort Edin Dizdarevic (Jan 24)